CMS MADE SIMPLE FORGE

CMS Made Simple Core

 

[#12288] CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker.

avatar
Created By: ww (fishyyh)
Date Submitted: Sat Apr 04 01:41:29 -0400 2020

Assigned To: Ruud van der Velden (ruudvdvelden)
Version: 2.2.14
CMSMS Version: 2.2.14
Severity: Minor
Resolution: Fixed
State: Closed
Summary:
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker.
Detailed Description:
1) Login into the application with the admin.
2)in the   Extensions > Fie Picker.
3)Add a new Profile ,and fill name with  the flowing
test'"><script>alert(/xsstest/)</script>
4)click submit
5) browse  File Picker and the XSS payload will get executed .


History

Comments
avatar
Date: 2020-09-18 12:01
Posted By: Ruud van der Velden (ruudvdvelden)

Fixed in svn (BR #12312)

Thanks for reporting
      
avatar
Date: 2020-11-03 14:24
Posted By: Rolf (rolf1)

CMSMS 2.2.15 has been released
      
Updates

Updated: 2020-11-03 14:24
state: Open => Closed

Updated: 2020-09-18 12:01
resolution_id: 5 => 7

Updated: 2020-09-18 12:01
resolution_id: => 5
severity_id: 1 => 3
assigned_to_id: 100 => 18365